Quantcast
RSS

Guide to SSL VPN

Best Practices for deploying SSL VPNs

Wide client support, authentication support are crucial

By Tim Green

• Part of the reason for using SSL VPNs is to allow users to connect using something other than a company-issued machine. If that is an important goal, check whether the product under consideration supports Windows, Linux, Mac and even the operating systems for handhelds and smart phones equipped with browsers.

• Check out the management platform and its ability to support multiple policies per user and user group. Because the technology can support such granular access, it may become desirable to issue more than one policy per person or group. For instance, a single user may require access rights that differ depending on what machine and what access method are used and what the security posture of the devices is.

• To tighten up security, use two-factor authentication to log into the VPN.

• Use options that delete from the remote machine any traces of transactions performed during the SSL VPN session. This is especially important if the corporation does not own the remote device and is readily accessible to others, such as a computer at an Internet kiosk.

• Use options that force sessions to time-out and demand reauthentication to prevent unauthorized access should the remote user walk away from the machine, leaving it vulnerable to someone else using it while it is logged into the VPN.

• Weigh how important SSL VPN access is to doing business. If it's essential, install gateways in high-availability mode, so if one gateway fails, the other can kick in.

• If SSL VPNs are to be used for network access in case of a disaster, build in capacity to handle the extra load. If the gateway is not sized to support all the additional users, it will become yet another problem after disaster strikes.

• Run penetration testing against the VPN. It allows access to corporate resources and is supposed to be secure, but it pays to check.

Was this article useful? Yes 0 No 0
Add Yours

Comments Readers reply with their ideas and expertise.

Subscribe to this discussion via email or RSS
  • What do you think?

  • Great year-end deals
    for small business!
  • Get 24/7 live remote AT&T Tech Support 360* service along with select Lenovo* PCs (with Intel® Core™ 2 Duo processors) and save up to 200!

    Learn more

  • HP EliteBook* 6930p Notebook with Intel® vPro™ technology and a free HP Basic Docking Station - $641 instant savings!

    Learn more

Business News Daily

Get the latest technology news that's important to you and your business, fresh seven days a week.

Featured Webcasts

Free Whitepapers

Software and Services Whitepapers from PC World

More whitepapers »

Whitepaper Alerts

Get updates on white papers, case studies, and spotlights on tech products and solutions for your business.

PC World's Marketplace

Sponsored Links